Learning path

Full curriculum

Full curriculum

Unit content

Public-key cryptography and key pairs

Public-key cryptography uses a pair of mathematically related keys with different roles:

  • a private key that must remain secret;
  • a public key that can be distributed.

For public-key encryption, anyone with the public key can encrypt a message intended for the private-key holder, while decryption requires the private key.

This changes the key-distribution problem: two parties do not need to share a secret in advance merely to send confidential data to one another.

The public key is not automatically trustworthy. An attacker who can replace a published key with their own can redirect protected communication unless the recipient has a trustworthy way to verify which key belongs to the intended party.

Public-key operations are generally more computationally expensive than symmetric encryption. Real protocols therefore often use public-key techniques to establish or verify short-lived symmetric keys, then protect bulk traffic with efficient symmetric cryptography.